Signals

2026-06-10 / OpenHands

hide_personal_workspaces is explicitly UI-only, not an access boundary

Edited by Michael Ruescher

What this changes for operators

  • PR #14741 (main, unreleased) hides personal workspaces in org-only installs but the docs state it is UI-only: the orgs API still returns personal orgs and there is no server-side enforcement. Operators must NOT treat it as an access-control boundary; the real boundary is the membership model.

Signal metadata

Source findings

Run: 2026-06-16-weekly-digest-2026-06-04_2026-06-16-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-06-10-openhands-personal-workspaces-ui-only

Research evidence and publication history are open in the repository.